mirror of
https://github.com/spring-projects/spring-boot.git
synced 2026-09-29 05:29:08 +00:00
Treat empty JWK Set URI as absent
Signed-off-by: Vinod Kumar <codingkiddo@gmail.com> See gh-50755
This commit is contained in:
committed by
Andy Wilkinson
parent
cd562c19de
commit
8eb3b032a4
+45
@@ -0,0 +1,45 @@
|
||||
/*
|
||||
* Copyright 2012-present the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* https://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package org.springframework.boot.security.oauth2.server.resource.autoconfigure;
|
||||
|
||||
import org.springframework.boot.autoconfigure.condition.ConditionMessage;
|
||||
import org.springframework.boot.autoconfigure.condition.ConditionOutcome;
|
||||
import org.springframework.boot.autoconfigure.condition.SpringBootCondition;
|
||||
import org.springframework.context.annotation.ConditionContext;
|
||||
import org.springframework.core.env.Environment;
|
||||
import org.springframework.core.type.AnnotatedTypeMetadata;
|
||||
import org.springframework.util.StringUtils;
|
||||
|
||||
/**
|
||||
* Condition for creating a JWT decoder using a JWK Set URI.
|
||||
*
|
||||
* @author Vinod Kumar M
|
||||
*/
|
||||
class JwkSetUriCondition extends SpringBootCondition {
|
||||
|
||||
@Override
|
||||
public ConditionOutcome getMatchOutcome(ConditionContext context, AnnotatedTypeMetadata metadata) {
|
||||
ConditionMessage.Builder message = ConditionMessage.forCondition("JWK Set URI Condition");
|
||||
Environment environment = context.getEnvironment();
|
||||
String jwkSetUri = environment.getProperty("spring.security.oauth2.resourceserver.jwt.jwk-set-uri");
|
||||
if (!StringUtils.hasText(jwkSetUri)) {
|
||||
return ConditionOutcome.noMatch(message.didNotFind("jwk-set-uri property").atAll());
|
||||
}
|
||||
return ConditionOutcome.match(message.foundExactly("jwk-set-uri property"));
|
||||
}
|
||||
|
||||
}
|
||||
+12
@@ -362,6 +362,18 @@ class OAuth2ResourceServerAutoConfigurationTests {
|
||||
assertThat(context.containsBean("jwtDecoderByIssuerUri")).isFalse();
|
||||
});
|
||||
}
|
||||
|
||||
@Test
|
||||
void autoConfigurationWhenIssuerUriPresentAndJwkSetUriEmptyShouldUseIssuerUri() {
|
||||
this.contextRunner
|
||||
.withPropertyValues("spring.security.oauth2.resourceserver.jwt.issuer-uri=https://issuer-uri.com",
|
||||
"spring.security.oauth2.resourceserver.jwt.jwk-set-uri=")
|
||||
.run((context) -> {
|
||||
assertThat(context).hasSingleBean(JwtDecoder.class);
|
||||
assertThat(context.containsBean("jwtDecoderByJwkKeySetUri")).isFalse();
|
||||
assertThat(context.containsBean("jwtDecoderByIssuerUri")).isTrue();
|
||||
});
|
||||
}
|
||||
|
||||
@Test
|
||||
void autoConfigurationWhenKeyLocationAndIssuerUriPresentShouldUseIssuerUri() throws Exception {
|
||||
|
||||
Reference in New Issue
Block a user